]> git.baikalelectronics.ru Git - kernel.git/commit
net/dccp: fix use-after-free in dccp_invalid_packet
authorEric Dumazet <edumazet@google.com>
Mon, 28 Nov 2016 14:26:49 +0000 (06:26 -0800)
committerDavid S. Miller <davem@davemloft.net>
Wed, 30 Nov 2016 01:37:26 +0000 (20:37 -0500)
commit5b7e22daddf937b14ca3363e1a06864b9da9d845
tree21a521e1c65060e4ef3060e122915134c29aa931
parentf3aed3e555f687d49a06997a58186c11e04e38e3
net/dccp: fix use-after-free in dccp_invalid_packet

pskb_may_pull() can reallocate skb->head, we need to reload dh pointer
in dccp_invalid_packet() or risk use after free.

Bug found by Andrey Konovalov using syzkaller.

Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: Andrey Konovalov <andreyknvl@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
net/dccp/ipv4.c